Friday, 23 March 2007

BBC on youtube

I only just noticed that BBC have a Youtube account. Kudos to them.

Wednesday, 21 March 2007

Free movie tickets

ANZ is having a promotion where they are giving away free Hoyts double movie tickets.

Call 1800 852 299 and leave your name, contact and address. Its as easy as that.

Friday, 2 March 2007

The PCI DSS (Payment Card Industry - Data Security Standard) defines who wears the loss when someone misuses your credit card. Essentially the blame rests with the merchant who will bear the cost of a fraudulent transaction.

Some bloggers have suggested that this is the appropriate spot to place the blame, suggesting that as the merchants are on the pointy of maintaining the security of the card information that they should be responsible for the breach - however this is entirely the wrong approach to take.

There is nothing that merchants can do to stop themselves from being defrauded & this is due to the fundamentally insecure way in which the transaction occurs. There are few, if any, solutions in place that would allow a merchant to validate whether or not the credit card number they've been provided actually belongs to the customer - all they can do is accept the risk of fraud & pass the costs of this on to the consumer. So under this model, no processes are improved & ultimately the consumer ends up paying for the cost of fraud anyway through increased prices.

The credit card companies, who are the only ones who can actually change the system, are left with no responsibility or financial penalties at all - and if they don't suffer then they won't change anything. If they were responsible to make good fraudulent transactions, you'd be sure that we'd have a more secure payment system in a short time.

You see while a particular merchant may be responsible for the leak of the credit card data - it likely will not be the merchant, or at least not alone, who will feel the pain of that leak. The stolen credit card data will be used to defraud other merchants, who may have protected their data quite well. So what incentive is there for a merchant to tightly protect the data when they'll still be impacted no matter how much they spend.

Consumers and merchants are both users of the credit card system - it is the credit card companies who are selling a service to these users & they alone are the ones responsible for fixing the insecurities in it.

Thursday, 1 March 2007

Google TV - NOT!

This video is an interesting one.



A guy by the name of Mark Erickson shows you how to sign up for Google TV - a service, he claims, that is in Beta release from Google that lets you watch television shows from major studios.

The video is a fake - Google TV doesn't exist, however Erickson does a good job of faking it.

While its fake, theres something about it that captures your attention. It'd be nice to be able to stream our favourite TV shows as easily as this. Ironically, within a few years this sort of service will likely be available & if I was in Google's shoes I'd be asking myself "Why not?".

TV studios make series to make money, they make this off of the distributors, who in turn make money off of the advertising. Now although the traditional method is to get advertising from broadcasting it over the air waves - whats wrong with broadcasting it over the Internet instead. YouTube has already proven that they're capable of streaming massive amounts of video simultaneously - so its not an infrastructure issue.

If the studios don't quickly adapt to what consumers want, a new breed of content producers will spring up that will deliver what is wanted... in fact, if they aren't there already then they're very close.

Tuesday, 6 February 2007

Google Maps gets fair dinkum'

Google Maps is now a full-cream service for Australians too.

For ages you've not been able to do routing on the Australian maps. Nor have you been able to search for businesses and types of businesses in Australia. This has severely limited the usefulness of google maps for Australia. For example, you'd try to find how far it was from one side of town to the other - but it wouldn't tell you the roads to travel - so this meant that it was great for looking at maps, but not for working with them.

But now you can find out how far it is from the "the gabba, brisbane" to "the melbourne cricket ground, melbourne" by using those exact terms... and instantly you'll learn that its a 21 hour 21 minute drive.

It's also nice to see that Google recognise they have a customer base in Australia and continue to deliver us the same services they get in the US, even if they are a bit delayed.

Saturday, 27 January 2007

Verified by Visa is just plain dumb

I hate the "Verified by Visa" program - it doesn't provide extra security... in fact it takes some away.

The whole concept of the verified by visa program is that when I pay online using my Visa card I get prompted to enter a password for my Visa card before the transaction can continue. This program is just dumb because using the VbV program is optional to merchants. This means that sometimes I get prompted to login to the program when using the card but, more often than not, I don't. So how does this protect me, the consumer? It doesn't... fake vendors will still attempt to steal credit cards from suckers and the suckers will keep giving it to them - outside of the VbV program.

But ahhh... I hear you say... the program isn't for the consumers... it's for the merchants, it verifies to them that the credit card is really being used by the owner of the card. No it doesn't! Because if I setup a fake merchant website to steal credit card details, all I need to do is add a popup at the end asking for the users VbV password... the user will happily give it to me because they've been trained to do this by Visa. You see when a merchant uses VbV I, as a consumer, get redirected from the merchants website to a supposedly Visa website (although it's not even on a visa.com URL) and asked to provide my password. This teaches users to give up their passwords to anyone who asks - bad Visa!

Similary, if someone had already stolen my credit card through some other means (and didn't have my VbV login) and they wanted to run up a bill on it or to extract money from it - they'd just choose a merchant who isn't using the VbV program - they're not prevented from using the credit card number in any real way.

If VISA really wanted a secure program then they would require you to log into your Visa account (or your bank account) and authorise the transaction apart from the merchants website... but they've skipped this step, no doubt, to make the transaction 'smoother'. The end result being that neither the customer nor the merchant are any more protected than they were before.

C'mon VISA - you should be doing more than training users to act in this way in the name of security theater.

Australia Day Caching

We had a great family day out geocaching for Australia Day. We all came home pretty tired, but its always nice to spend time together.

And here's the video!!!

Recent Geocaching Logs

Stuff I"ve read lately